Bug #91387

Relax constraints on serializing objects

Added by Oliver Hader about 1 year ago. Updated 12 months ago.

Status:
Closed
Priority:
Should have
Assignee:
Category:
Security
Target version:
Start date:
2020-05-13
Due date:
% Done:

100%

Estimated time:
TYPO3 Version:
9
PHP Version:
Tags:
Complexity:
Is Regression:
Yes
Sprint Focus:

Description

With security advisory https://typo3.org/security/advisory/TYPO3-CORE-SA-2020-004 new BlockSerializationTrait has been introduced blocking serialization and deserialization for a couple of classes (see advisory for details). Since this cause a couple of side-effects for valid use-cases, the restriction on serialize() is removed - which is fine from a security point of view.

Possible use case:
Some system state has to be persisted for documentation purposes, which needs a working serialization. De-serialization is not needed in such cases.
Reported by Gernot Leitgab in https://typo3.slack.com/archives/C0K5MU94J/p1589366052028100


Related issues

Related to TYPO3 Core - Bug #91393: Cachingproblems after recent TYPO3 9.5.17 Closed2020-05-14

Actions
Related to TYPO3 Core - Bug #88613: Replace ObjectStorage & LazyObjectStorage with symfony/collectionAccepted2019-06-21

Actions
Related to TYPO3 Core - Bug #91404: After update from 9.5.16 to 9.5.17 I get an error 'Cannot serialize'Closed2020-05-14

Actions
Related to TYPO3 Core - Bug #91364: Extbase/CachingFramework - Serialization on 'Closure' is not allowedNeeds Feedback2020-05-12

Actions
#1

Updated by Oliver Hader about 1 year ago

  • Is Regression set to Yes
#2

Updated by Gerrit Code Review about 1 year ago

  • Status changed from New to Under Review

Patch set 1 for branch master of project Packages/TYPO3.CMS has been pushed to the review server.
It is available at https://review.typo3.org/c/Packages/TYPO3.CMS/+/64486

#3

Updated by Gerrit Code Review about 1 year ago

Patch set 2 for branch master of project Packages/TYPO3.CMS has been pushed to the review server.
It is available at https://review.typo3.org/c/Packages/TYPO3.CMS/+/64486

#4

Updated by Gerrit Code Review about 1 year ago

Patch set 3 for branch master of project Packages/TYPO3.CMS has been pushed to the review server.
It is available at https://review.typo3.org/c/Packages/TYPO3.CMS/+/64486

#5

Updated by Markus Klein about 1 year ago

  • Description updated (diff)
#6

Updated by Benjamin Franzke about 1 year ago

  • Description updated (diff)
#7

Updated by Gerrit Code Review about 1 year ago

Patch set 1 for branch 9.5 of project Packages/TYPO3.CMS has been pushed to the review server.
It is available at https://review.typo3.org/c/Packages/TYPO3.CMS/+/64370

#8

Updated by Oliver Hader about 1 year ago

  • Related to Bug #91393: Cachingproblems after recent TYPO3 9.5.17 added
#9

Updated by Oliver Hader about 1 year ago

  • Status changed from Under Review to Resolved
  • % Done changed from 0 to 100
#10

Updated by Oliver Hader about 1 year ago

  • Target version set to 9.5.18 & 10.4.3
#11

Updated by Oliver Hader about 1 year ago

  • Related to Bug #88613: Replace ObjectStorage & LazyObjectStorage with symfony/collection added
#12

Updated by Oliver Hader about 1 year ago

  • Related to Bug #91404: After update from 9.5.16 to 9.5.17 I get an error 'Cannot serialize' added
#13

Updated by Oliver Hader 12 months ago

  • Related to Bug #91364: Extbase/CachingFramework - Serialization on 'Closure' is not allowed added
#14

Updated by Benni Mack 12 months ago

  • Status changed from Resolved to Closed

Also available in: Atom PDF